Boosted by db@social.lol ("David Bushell 🪿"):
zachleat@zachleat.com ("Zach Leatherman") wrote:
WordPress updates required: https://wordpress.org/news/2026/07/wordpress-7-0-2-release/
> The attack has no preconditions and can be exploited by an anonymous user in a stock install of WordPress with no plugins — https://slcyber.io/research-center/wp2shell-pre-authentication-rce-in-wordpress-core/